Systems and methods for dynamic biometric configuration compliance control
Abstract
Systems and methods for dynamically-configured compliance control are disclosed. According to one embodiment, a method may include (1) receiving, from an electronic device, a transaction request for a user that requires authentication; (2) at least one computer processor determining a target security level for the transaction; (3) the at least one computer processor determining a location of the electronic device; (4) the at least one computer processor determining at least one restriction on conducting the transaction based on the location of the electronic device; (5) the at least one computer processor determining at least one authentication configuration that meets the target security level and the at least one restriction on conducting the transaction; and (6) the at least one computer processor receiving user data in accordance with the authentication configuration.
Claims
exact text as granted — not AI-modified1 . A method for dynamically-configured compliance control, comprising:
receiving, from an electronic device, a transaction request for a user that requires authentication; at least one computer processor determining a target security level for the transaction; the at least one computer processor determining a location of the electronic device; the at least one computer processor determining at least one restriction on conducting the transaction based on the location of the electronic device; the at least one computer processor determining at least one authentication configuration that meets the target security level and the at least one restriction on conducting the transaction, the authentication configuration comprising at least one of an authentication modality and an electronic device configuration; and the at least one computer processor receiving user data in accordance with the authentication configuration.
2 . The method of claim 1 , further comprising:
the at least one computer processor determining at least one risk factor based on historical transaction data for at least one of the user and a type for the transaction.
3 . The method of claim 1 , further comprising:
the at least one computer processor performing statistical analysis on the transaction.
4 . The method of claim 1 , further comprising:
the at least one computer processor analyzing at least one of the transaction and the user for an anomaly.
5 . The method of claim 1 , wherein the restriction is on a manner of user authentication.
6 . The method of claim 1 , wherein the restriction is at least one legal requirement on a manner in which the transaction is conducted.
7 . The method of claim 6 , wherein the at least one legal requirement is one of a law and a regulation.
8 . The method of claim 6 , wherein the at least one legal requirement comprises at least a first level legal requirement and a second level legal requirement.
9 . The method of claim 8 , further comprising:
the at least one computer processor determining a hierarchy associated with first level legal requirement and the second level legal requirement; and the at least one computer processor selecting the restriction based on the determination.
10 . The method of claim 1 , further comprising:
the at least one computer processor determining at least one policy restriction on conducting the transaction; and wherein the at least one computer processor determines the at least one authentication configuration to meet the target security level, the at least one restriction on conducting the transaction, and the policy restriction.
11 . The method of claim 1 , wherein the authentication modality is selected from a plurality of available authentication modalities.
12 . The method of claim 1 , wherein the electronic device configuration is based on at least one electronic device specification.
13 . The method of claim 12 , wherein the electronic device specification identifies a characteristic for an available input on the electronic device.
14 . The method of claim 1 , further comprising:
completing the transaction with the authentication configuration.
15 . The method of claim 1 , wherein the authentication configuration comprises at least one biometric.
16 . The method of claim 1 , wherein there are a plurality of hierarchies for a plurality of restrictions, and wherein the at least one computer determines at least one authentication configuration by one of merging the hierarchies and resolving conflicts in the hierarchies.
17 . A system for dynamic compliance control, comprising:
a user electronic device comprising:
at least one computer processor that receives a transaction request from a user; and
a compliance interface executed by the at least one computer processor;
a back-end comprising:
at least one interface for receiving the transaction request from the compliance interface;
a restriction matrix that stores at least one transaction restriction; and
at least one back-end computer processor that performs the following:
determine a target security level for the transaction;
determine at least one restriction on conducting the transaction based on the location of the electronic device;
determine at least one authentication configuration that meets the target security level and the at least one restriction on conducting the transaction, the authentication configuration comprising at least one of an authentication modality and an electronic device configuration; and
receive user data in accordance with the authentication configuration.
18 . The system of claim 17 , wherein the at least one back-end computer processor further determines at least one risk factor based on historical transaction data for at least one of the user and a type for the transaction.
19 . The system of claim 17 , wherein the back-end further comprises a statistical analysis engine that performs statistical analysis on the transaction.
20 . The system of claim 17 , wherein the back-end further comprises an anomaly engine that analyzes at least one of the transaction and the user for an anomaly.
21 . The system of claim 17 , wherein the restriction is on a manner of user authentication.
22 . The system of claim 17 , wherein the restriction is at least one legal requirement on a manner in which the transaction is conducted.
23 . The system of claim 22 , wherein the at least one legal requirement comprises at least first level legal requirement and a second level legal requirement
24 . The system of claim 22 , wherein the back-end processor further:
determines a hierarchy associated with first level legal requirement and the second level legal requirement; and selects the restriction based on the determination.
25 . The system of claim 17 , wherein the back-end processor further:
determines at least one policy restriction on conducting the transaction; and determines the at least one authentication configuration to meet the target security level, the at least one restriction on conducting the transaction, and the policy restriction.
26 . The system of claim 17 , wherein the authentication modality is selected from a plurality of available authentication modalities.
27 . The system of claim 17 , wherein the electronic device configuration is based on at least one electronic device specification.
28 . The system of claim 27 , wherein the electronic device specification identifies a characteristic for an available input on the electronic device.
29 . The system of claim 17 , wherein the authentication configuration comprises at least one biometric.
30 . The system of claim 17 , wherein the user electronic device further comprises a cache version of the restriction matrix.Join the waitlist — get patent alerts
Track US2015242840A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.